VYPR
Unrated severityNVD Advisory· Published Aug 15, 2026

CVE-2026-74455

CVE-2026-74455

Description

In the Linux kernel, the following vulnerability has been resolved:

can: peak_usb: validate uCAN receive record lengths

pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer.

Require each record to contain the fixed header for its type, and verify CAN payload bytes before copying them into the skb.

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.